Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Derivation of fixlist.txt for FarBar


  • This topic is locked This topic is locked
3 replies to this topic

#1 MoondogMatt

MoondogMatt

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:59 AM

Posted 20 May 2014 - 04:52 PM

I'm curious how the personalized fixlist.txt is made. I have a FRST.txt for you guys that I would like to have made up, but I would also like to know how it's done, so I could make my own in the future

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013 (ATTENTION: ====> FRST version is 187 days old and could be outdated)
Ran by SYSTEM on MININT-CHP0K04 on 20-05-2014 14:33:32
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [] - [x]
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe [590256 2011-05-17] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [972672 2011-04-27] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2011-06-09] (TOSHIBA Corporation)
HKLM\...\Run: [TosNC] - C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe [597936 2011-07-27] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38824 2011-06-28] (TOSHIBA Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [ToshibaServiceStation] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe [3218864 2011-06-22] (Toshiba)
HKLM-x32\...\Run: [ToshibaAppPlace] - C:\Program Files (x86)\TOSHIBA\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [LTCM Client] - C:\Program Files (x86)\LTCM Client\ltcmClient.exe [1583808 2009-03-02] (Leader Technologies Inc.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2557976 2014-05-02] ()
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKU\justin\...\Run: [Messenger (Yahoo!)] - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\justin\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-02-17] (Google Inc.)
HKU\justin\...\Run: [EPSON PictureMate PM 225] - C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFOA.EXE /FU "C:\Users\justin\AppData\Local\Temp\E_SC386.tmp" /EF "HKCU"
HKU\justin\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\System32\spool\drivers\x64\3\E_IATIIBE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\justin\...\Run: [EPLTarget\P0000000000000002] - C:\Windows\System32\spool\drivers\x64\3\E_IATIIBE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1355552 2014-04-08] (Conduit)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1050912 2014-04-08] (Conduit)
Startup: C:\Users\justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
Startup: C:\Users\justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)

==================== Services (Whitelisted) =================

S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [32808 2013-07-01] (Just Develop It)
S2 CltMngSvc; C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe [2470688 2014-04-08] (Conduit)
S2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [8998800 2013-05-08] (DisplayLink Corp.)
S2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
S2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe [138760 2011-08-10] (Symantec Corporation)
S2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\PC Checkup\SymcPCCULaunchSvc.exe [132504 2013-09-17] (Symantec Corporation)
S2 PasswordBox; C:\Program Files (x86)\PasswordBox\pbbtnService.exe [67584 2013-11-01] (PasswordBox, Inc.)
S2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [126392 2011-07-19] (Symantec Corporation)
S2 vToolbarUpdater18.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe [1801240 2014-05-02] (AVG Secure Search)

==================== Drivers (Whitelisted) ====================

S1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [50464 2014-05-02] (AVG Technologies)
S3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120711.002\BHDrvx64.sys [1161376 2012-06-18] (Symantec Corporation)
S3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1301000.01C\ccSetx64.sys [167048 2011-08-08] (Symantec Corporation)
S3 DisplayLinkUsbIo_x64; C:\Windows\System32\DRIVERS\DisplayLinkUsbIo_x64_7.2.47873.0.sys [44944 2013-05-13] ()
S3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-19] (Symantec Corporation)
S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-19] (Symantec Corporation)
S3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120803.002\IDSvia64.sys [509088 2012-07-05] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120804.009\ENG64.SYS [120440 2012-08-04] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120804.009\EX64.SYS [2068600 2012-08-04] (Symantec Corporation)
S3 SRTSP; C:\Windows\system32\drivers\NISx64\1301000.01C\SRTSP64.SYS [729720 2011-08-02] (Symantec Corporation)
S3 SRTSPX; C:\Windows\system32\drivers\NISx64\1301000.01C\SRTSPX64.SYS [37496 2011-08-02] (Symantec Corporation)
S3 SymDS; C:\Windows\system32\drivers\NISx64\1301000.01C\SYMDS64.SYS [451192 2011-07-25] (Symantec Corporation)
S3 SymEFA; C:\Windows\system32\drivers\NISx64\1301000.01C\SYMEFA64.SYS [1084536 2011-07-28] (Symantec Corporation)
S3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2012-02-17] (Symantec Corporation)
S3 SymIRON; C:\Windows\system32\drivers\NISx64\1301000.01C\Ironx64.SYS [189560 2011-07-25] (Symantec Corporation)
S3 SymNetS; C:\Windows\system32\drivers\NISx64\1301000.01C\SYMNETS.SYS [401016 2011-07-25] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-20 14:21 - 2014-05-20 14:21 - 00000000 ____D C:\FRST
2014-05-06 02:16 - 2014-05-20 12:16 - 00000392 _____ C:\Windows\setupact.log
2014-05-06 02:16 - 2014-05-06 02:16 - 00000000 _____ C:\Windows\setuperr.log
2014-05-02 15:17 - 2014-05-02 15:17 - 00000000 ____D C:\ProgramData\AVG Secure Search
2014-05-02 06:26 - 2014-05-02 06:26 - 00021253 _____ C:\Users\justin\Desktop\Household stuff.xlsx
2014-05-02 02:00 - 2014-04-29 06:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-05-02 02:00 - 2014-04-29 05:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-05-02 02:00 - 2014-04-29 04:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-02 02:00 - 2014-04-29 04:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-28 10:30 - 2014-04-28 10:30 - 17931952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-04-23 14:31 - 2014-05-05 10:39 - 00046945 _____ C:\Users\justin\Desktop\Bills 2014.xlsx

==================== One Month Modified Files and Folders =======

2014-05-20 14:21 - 2014-05-20 14:21 - 00000000 ____D C:\FRST
2014-05-20 13:14 - 2009-07-13 21:38 - 00025600 ___SH C:\Windows\System32\config\BCD-Template.LOG
2014-05-20 13:14 - 2009-07-13 21:32 - 00028672 _____ C:\Windows\System32\config\BCD-Template
2014-05-20 12:16 - 2014-05-06 02:16 - 00000392 _____ C:\Windows\setupact.log
2014-05-17 15:05 - 2012-02-17 20:57 - 01693136 _____ C:\Windows\WindowsUpdate.log
2014-05-06 21:12 - 2012-02-17 21:31 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-06 20:30 - 2013-12-28 08:44 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-06 20:30 - 2009-07-13 20:45 - 00024608 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-06 20:30 - 2009-07-13 20:45 - 00024608 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-06 19:07 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-05-06 02:16 - 2014-05-06 02:16 - 00000000 _____ C:\Windows\setuperr.log
2014-05-06 02:15 - 2014-02-12 11:10 - 00000000 ___RD C:\Users\justin\Dropbox
2014-05-06 02:12 - 2014-02-12 11:09 - 00000000 ____D C:\Users\justin\AppData\Roaming\Dropbox
2014-05-05 22:36 - 2013-07-15 16:36 - 00001194 _____ C:\Windows\Tasks\weDownload-codedownloader.job
2014-05-05 22:36 - 2013-07-15 16:36 - 00001190 _____ C:\Windows\Tasks\weDownload-updater.job
2014-05-05 22:36 - 2013-07-15 16:36 - 00001094 _____ C:\Windows\Tasks\weDownload-enabler.job
2014-05-05 22:35 - 2013-07-15 16:35 - 00001900 _____ C:\Windows\Tasks\weDownload-chromeinstaller.job
2014-05-05 15:43 - 2013-11-23 10:32 - 00000000 ____D C:\Windows\Minidump
2014-05-05 15:04 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2014-05-05 15:00 - 2014-04-07 14:51 - 00010327 _____ C:\Users\justin\Documents\Agenda 7 April 2014.xlsx
2014-05-05 14:49 - 2012-02-17 21:31 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-05 10:39 - 2014-04-23 14:31 - 00046945 _____ C:\Users\justin\Desktop\Bills 2014.xlsx
2014-05-03 14:42 - 2013-06-21 22:07 - 00000000 ____D C:\Users\justin\AppData\Local\CrashDumps
2014-05-03 14:41 - 2009-07-13 21:13 - 00782510 _____ C:\Windows\System32\PerfStringBackup.INI
2014-05-02 19:18 - 2013-07-15 16:36 - 00000000 ____D C:\Users\justin\AppData\Local\AVG SafeGuard toolbar
2014-05-02 15:17 - 2014-05-02 15:17 - 00000000 ____D C:\ProgramData\AVG Secure Search
2014-05-02 15:17 - 2013-11-05 07:26 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2014-05-02 15:17 - 2013-07-31 05:07 - 00000000 ____D C:\Windows\SysWOW64\cache
2014-05-02 15:17 - 2013-07-15 16:36 - 00050464 _____ (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys
2014-05-02 06:26 - 2014-05-02 06:26 - 00021253 _____ C:\Users\justin\Desktop\Household stuff.xlsx
2014-04-29 06:01 - 2014-05-02 02:00 - 23547904 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-04-29 05:40 - 2014-05-02 02:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-04-29 04:48 - 2014-05-02 02:00 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 04:34 - 2014-05-02 02:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-28 19:40 - 2013-06-01 20:06 - 00003962 _____ C:\Windows\System32\Tasks\PC Checkup 3 Weekly Scan
2014-04-28 10:30 - 2014-04-28 10:30 - 17931952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-04-28 10:30 - 2013-12-28 08:44 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-28 10:30 - 2012-07-06 07:14 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-28 10:30 - 2011-10-30 18:34 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-22 19:32 - 2012-12-03 12:03 - 00000000 ____D C:\Users\justin\Documents\stuff
2014-04-22 18:39 - 2010-11-20 19:47 - 00177168 _____ C:\Windows\PFRO.log

Some content of TEMP:
====================
C:\Users\justin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuwk2bi.dll
C:\Users\justin\AppData\Local\Temp\ose00000.exe
C:\Users\justin\AppData\Local\Temp\_is2A89.exe
C:\Users\justin\AppData\Local\Temp\_is35A0.exe
C:\Users\justin\AppData\Local\Temp\_isE233.exe


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================


==================== Memory info ===========================

Percentage of memory in use: 22%
Total physical RAM: 4043.86 MB
Available physical RAM: 3122.52 MB
Total Pagefile: 4042.06 MB
Available Pagefile: 3201.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.87 MB

==================== Drives ================================

Drive c: (TI106321W0B) (Fixed) (Total:282.96 GB) (Free:210.76 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.27 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.28 GB) (Free:0 GB) UDF
Drive g: (PHOENIX) (Removable) (Total:14.9 GB) (Free:1.33 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 010ED62A)
Partition 1: (Active) - (Size=1 GB) - (Type=27)
Partition 2: (Not Active) - (Size=283 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=14 GB) - (Type=17)

========================================================
Disk: 2 (Size: 15 GB) (Disk ID: 22B1AEA0)
Partition 1: (Not Active) - (Size=15 GB) - (Type=0C)


LastRegBack: 2014-04-28 23:30

==================== End Of Log ============================



BC AdBot (Login to Remove)

 


m

#2 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,015 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:04:59 PM

Posted 23 May 2014 - 10:30 AM

Greetings and :welcome: to BleepingComputer,
My name is xXToffeeXx, but feel free to call me Toffee if it is easier for you. I will be helping you with your malware problems.
 
A few points to cover before we start:

  • Do not run any tools without being instructed to as this makes my job much harder in trying to figure out what you have done.
  • Make sure to read my instructions fully before attempting a step.
  • If you have problems or questions with any of the steps, feel free to ask me. I will be happy to answer any questions you have.
  • Please follow the topic by clicking on the "Follow this topic" button, and make sure a tick is in the "receive notifications" and is set to "Instantly". Any replies should be made in this topic by clicking the "Reply to this topic" button.
  • Important information in my posts will often be in bold, make sure to take note of these.
  • I will attempt to reply as soon as possible, and normally within 24 hours of your reply. If this is not possible or I have a delay then I will let you know.
  • I will bump a topic after 3 days of no activity, and then will give you another 2 days to reply before a topic is closed. If you need more time than this please let me know.
  • Lets get going now :thumbup2:

==========================
 
Hi MoondogMatt,
 
Can your computer not boot normally? I see you ran FRST from RE with an extremely outdated version of FRST.
 
What current troubles are you having?
 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

~Currently in my last year of school, so replies might be more delayed~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#3 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,015 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:04:59 PM

Posted 27 May 2014 - 05:09 AM

Hi MoondogMatt,
 
This is a 3 day bump:
 
It has been more than 3 days since my last post.

  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

~Currently in my last year of school, so replies might be more delayed~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#4 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,015 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:04:59 PM

Posted 31 May 2014 - 04:28 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

~If I am helping you and you have not had a reply from me in two days, please send me a PM~

~Currently in my last year of school, so replies might be more delayed~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users